SOC Analyst
IBM
Job Description
Position
IBM Amsterdam, North Holland, Netherlands
We are looking for an SOC Analyst to join our Cybersecurity Operations team.
Introduction
The IBM CISO SOC in Amsterdam is expanding into a multiâdisciplinary team that protects the IBM organization around the clock against threats both internal and external, with a focus on EUâlocated assets and networks. We perform security event detection, response and remediation, working closely with forensic analysts, threat hunters, threat intelligence, and platform engineers. As time is our most valuable resource, automation and tuning are key to avoid investigating the same false positive repeatedly.
Required Professional and Technical Expertise
- Minimum 3+ years of experience working within a SOC, Threat Hunt, or Threat Intel team
- Experience with Linux, Windows and macOS systems
- Critical thinking and problemâsolving skills
- Passion for information security and data security
- Strong written and verbal communication skills
- Strong interpersonal and organizational skills
Preferred Professional and Technical Expertise
- At least 2 yearsâ experience in Incident Response in a global corporate enterprise
- Experience in fastâpaced investigations
- Experience with programming or scripting languages
- Familiarity with IBM QRadar SIEM, Windows Defender ATP and EDR platforms is a plus
Your Role and Responsibilities
- Security monitoring: analyze detections and alerts and respond to security threats from firewalls, IDS, IPS, AV, EDR and other security threat data sources.
- Conduct security monitoring activities to provide depth visibility into potential known and unknown threats that may pose risk to the IBM environment.
- Document actions in cases to effectively communicate information to internal stakeholders and for historical retrieval.
- Resolve problems independently and understand escalation procedures.
- Participate in security incidents and act as the technical subjectâmatter expert during significant incidents.
- Operate cyberâsecurity incident response technologies, including network logging and forensics, SIEM tools, security analytics platforms, logâsearch technologies, and hostâbased forensics as applicable.
- Act as an internal informationâsecurity consultant to business and technology units, advising on risks, threats and control practices related to rapid response.
- Assist in development and knowledge sharing within the team.
- Assist in security console tuning.
- Assist in establishing global security monitoring discipline to support the enterprise.
- Identify and share threat intelligence that impacts IBM and its customers or products.